Vulnerabilities > CVE-2006-6554 - Unspecified vulnerability in Kerio Mailserver
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN kerio
nessus
Summary
Unspecified vulnerability in Kerio MailServer before 6.3.1 allows remote attackers to cause a denial of service (segmentation fault and service stop) via certain long LDAP queries, as demonstrated by vd_kms6.pm.
Vulnerable Configurations
Nessus
NASL family | Denial of Service |
NASL id | KERIO_KMS_631.NASL |
description | The remote host is running Kerio MailServer, a commercial mail server available for Windows, Linux, and Mac OS X platforms. According to its banner, the LDAP service associated with the installed version of Kerio MailServer terminates abnormally when it receives certain malformed LDAP search requests. An unauthenticated, remote attacker can exploit this issue to deny access to legitimate users. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 23868 |
published | 2006-12-15 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/23868 |
title | Kerio MailServer < 6.3.1 Long LDAP Query DoS |
code |
|
References
- http://secunia.com/advisories/23364
- http://secunia.com/advisories/23364
- http://www.kerio.com/kms_history.html
- http://www.kerio.com/kms_history.html
- http://www.securityfocus.com/archive/1/454455/100/0/threaded
- http://www.securityfocus.com/archive/1/454455/100/0/threaded
- http://www.vupen.com/english/advisories/2006/4993
- http://www.vupen.com/english/advisories/2006/4993
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30872
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30872